Internal audit concepts
Internal audit provides independent, objective assurance and consulting designed to add value and improve an organisation’s operations. Nextera Trace is built around the professional cycle rather than around a generic task tracker, so this page covers that cycle.
Independence is a constraint on the system, not just on the people
Section titled “Independence is a constraint on the system, not just on the people”The defining characteristic of internal audit is that it is independent of the activities it audits. Independence is organisational — internal audit reports functionally to the audit committee and administratively to management — and objectivity is the individual equivalent: no auditor assesses work they performed or advised on.
This has direct consequences for how an audit system must behave, which is why it belongs on a concepts page rather than in a policy document:
- Management can be given read access to results, but must not be able to alter a finding, its rating, or its evidence.
- The person who agrees a management action and the person who verifies it was completed cannot be the same person.
- The audit trail on ratings and conclusions matters more than in most systems, because the value of a finding is partly its unamended provenance.
The audit charter is the board-approved document establishing internal audit’s purpose, authority, reporting lines and right of access. Everything else derives from it. Internal audit’s professional framework comes from the Institute of Internal Auditors.
The audit universe
Section titled “The audit universe”The audit universe is the complete population of things that could be audited — entities, business units, processes, systems, geographies, third parties, and risk themes.
Two properties make it useful rather than decorative:
- It is maintained, not rebuilt. A universe reconstructed each year loses the history of what was audited when, which is the input the plan most needs.
- Its granularity is consistent. A universe mixing “the Surabaya branch” with “the entire finance function” cannot be prioritised sensibly, because the units are not comparable.
Each auditable unit carries risk attributes, an owner, and — crucially — when it was last audited and what was found.
Coverage is the question the universe exists to answer: what proportion of the universe, weighted by risk, has been audited within the cycle? An area never audited in five years is a finding about the plan, not about the area.
Risk-based planning
Section titled “Risk-based planning”The annual plan is built from the universe, prioritised by risk. A defensible plan usually weighs:
- Inherent risk of the auditable unit — materiality, complexity, change, regulatory exposure, fraud susceptibility.
- Control maturity, where known — often informed by the organisation’s ICoFR work in a system like Nextera Guard.
- Time since last audit, and what that audit found.
- Management and audit committee requests, held in tension with independence: internal audit takes input on the plan, but the plan is not set by the auditee.
- Available resource — the plan is constrained by auditor days, and pretending otherwise produces a plan that fails in Q3.
Assurance mapping is the discipline of recording who else already provides assurance over each area — external audit, regulators, second-line functions, certification bodies — so internal audit can direct effort where it is the only assurance, rather than duplicating.
Plans change. What matters is that changes are visible and approved, not that the plan was perfect in January.
Executing an engagement
Section titled “Executing an engagement”An engagement runs through a recognisable sequence:
- Scope and terms of reference. Objectives, boundaries, period, criteria, and the engagement’s own risk assessment. Agreed with the auditee, approved within audit.
- Planning. The audit programme — what will be tested, how, and by whom.
- Fieldwork. Performing the tests and gathering evidence.
- Working papers. The record of what was done.
- Findings. Raised, discussed, and agreed with management.
- Report. Issued to management and, in summary, to the audit committee.
- Follow-up. Verification that agreed actions were completed.
Working papers carry a specific professional standard: a competent reviewer with no prior connection to the engagement should be able to read them and understand what was tested, what was found, and why the conclusion follows. That standard — not tidiness — is what makes working paper structure worth enforcing.
Review is the corresponding control: work is reviewed by someone more senior before conclusions are issued, and the review itself is evidenced.
The five elements of a finding
Section titled “The five elements of a finding”Every well-formed finding has all five. Missing elements are the most common reason a finding is disputed or ignored:
| Element | The question it answers |
|---|---|
| Criteria | What should be happening — policy, standard, regulation, control design |
| Condition | What is happening |
| Cause | Why the gap exists |
| Effect | What the gap could lead to — quantified wherever possible |
| Recommendation | What should change |
Cause is the element most often skipped, and it is the one that determines whether remediation works. A finding that says “reconciliations were not performed” without establishing why — no owner, no time, no system access, no understanding of the requirement — produces a management action that fixes the symptom and recurs next year.
Effect is what converts a finding from an observation into a priority. “Three of twenty reconciliations were late” is an observation; “three of twenty reconciliations were late, covering IDR 40 billion of balances, and one contained an uncorrected error” is a finding.
Rating
Section titled “Rating”Ratings exist so that limited management attention goes to the right places. Any scale works as long as it is defined, applied consistently, and calibrated against impact and likelihood rather than against how annoyed the auditor was.
Two rating levels are usually needed and often confused:
- Finding rating — the severity of the individual issue.
- Engagement opinion — the overall conclusion on the area audited. An area can receive several low findings and still warrant an adverse overall opinion if together they show the control environment is weak.
Definitions should be published in the methodology and applied by the same people who wrote them. An unwritten scale becomes a negotiation.
Management response and follow-up
Section titled “Management response and follow-up”Each finding gets a management response containing three things and no fewer: an agreed action, a named owner, and a due date. “Noted” is not a response.
Where management accepts the risk rather than acting, that is a legitimate outcome — but it must be explicitly recorded as risk acceptance at an appropriate level of authority, not allowed to become a permanently overdue action.
Follow-up is where most audit functions lose value, and the reason is structural rather than cultural. Findings are raised in engagement-shaped batches, but they come due continuously and long after the engagement closed. If actions live in the engagement’s own file, nobody can answer the audit committee’s actual question — how many high-rated actions are overdue across everything? — without reassembling it by hand.
Verification closes the loop: internal audit confirms the action was completed and, more importantly, that it addressed the cause. Closing on management’s assertion alone undermines the whole cycle.
Reporting to the committee
Section titled “Reporting to the committee”Audit committee reporting is a different product from an engagement report, drawn from the same data: plan progress against the approved plan, coverage of the universe, findings by rating and by theme, overdue actions with ageing, and matters the committee needs to decide.
The value of generating it from the same underlying records is that the numbers cannot drift between the engagement file and the committee pack — which is the failure mode of every spreadsheet-based audit function.
How these concepts map to Nextera Trace
Section titled “How these concepts map to Nextera Trace”| Concept on this page | Nextera Trace module |
|---|---|
| The maintained population of auditable entities and processes | Audit universe |
| Risk-based prioritisation into an approved annual plan | Audit planning |
| Scope, fieldwork and working papers for each engagement | Audit execution |
| The five elements, rating, and agreement with management | Findings & recommendations |
| Agreed actions tracked to closure with live status | Follow-up tracking |
| Engagement and committee reporting from the same data | Audit reporting |